Courseiva

SK0-005 · topic practice

security-disaster-recovery practice questions

Practise CompTIA Server+ SK0-005 security-disaster-recovery practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: security-disaster-recovery

What the exam tests

What to know about security-disaster-recovery

security-disaster-recovery questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common security-disaster-recovery exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

security-disaster-recovery questions

20 questions · select your answer, then reveal the explanation

A server administrator is restoring a file server from a full backup taken 7 days ago and incremental backups taken daily. The restoration fails with an error about missing catalog files. What is the most likely cause?

A medium-sized company uses a backup strategy that includes a full backup every Sunday at 2:00 AM and differential backups Monday through Saturday at 2:00 AM. The backups are written to a network-attached storage (NAS) device. On Thursday morning, the company experiences a ransomware attack that encrypts all data on the file server, including the NAS. The administrator needs to restore the file server with minimal data loss. The last successful full backup was from the previous Sunday, and differential backups were successful on Monday, Tuesday, and Wednesday. However, Thursday's differential was not completed because the attack occurred before the scheduled time. The administrator attempts to restore using the Sunday full backup and Thursday's differential, but the restore fails because the differential backup on the NAS is also encrypted. Which of the following is the best course of action?

A small business has a single file server running Windows Server 2019. The server uses two internal SATA drives in a RAID 1 mirror for the operating system and data. The company's backup solution performs a full backup every night to an external USB hard drive, which is stored in the server room. The IT administrator recently noticed that the server's system volume is running low on space and decides to migrate the data to a larger drive. During the migration, the server crashes and will not boot. The administrator attempts to restore from the latest backup but finds that the backup drive is corrupted and cannot be read. The company has no offsite backups. What should the administrator have done to prevent this situation?

A medium-sized company runs an e-commerce platform on a cluster of three physical servers hosting virtual machines. The disaster recovery plan includes daily backups to a remote data center using Veeam Backup & Replication. The company's annual disaster recovery drill is scheduled for next week. During the drill, the IT team plans to simulate a complete site failure by powering off the primary data center. The recovery time objective (RTO) is 4 hours, and the recovery point objective (RPO) is 1 hour. The team successfully restores the VMs at the remote site, but the application experiences significant performance degradation and many transactions fail due to database inconsistency. Investigation reveals that the backup was taken at 2:00 AM, but the failure occurred at 10:00 AM, and the application's database had transactions between 2:00 AM and 10:00 AM that were not captured. What should the IT team do to improve the recovery process?

A large enterprise uses a centralized backup solution with a backup server running Commvault. Backups are stored on a deduplicated disk array and replicated to a secondary site for disaster recovery. The company's security team detects ransomware activity that has encrypted several file servers. The backup administrator checks the backup repository and finds that the backup data is also encrypted because the backup service account had permissions to modify backup files, and the ransomware propagated to the repository. The last known good backup is from two weeks ago, which is too old for the organization's RPO of 24 hours. The backup administrator is under pressure to restore operations quickly. Which of the following should the administrator implement to prevent this from recurring?

A company uses a two-node failover cluster for a critical application. The cluster nodes are located in the same data center, and the quorum configuration uses a file share witness on a separate server in the same data center. During a major power outage, both cluster nodes and the file share witness server lose power. What is the impact on cluster availability?

A server administrator is responsible for protecting sensitive data. The backup process copies files to a network share daily. Which of the following should the administrator do to BEST ensure the confidentiality of the backup data both during transfer and at rest?

Refer to the exhibit. An administrator is reviewing logs after a server experienced performance issues and unexpected shutdowns. Based on the log entries, which component is MOST likely failing?

Exhibit

[12345.678] sd 0:0:0:0: [sda] Unhandled sense code
[12345.678] sd 0:0:0:0: [sda] Result: hostbyte=DID_OK driverbyte=DRIVER_SENSE
[12345.678] sd 0:0:0:0: [sda] Sense Key : Medium Error [current]
[12345.678] sd 0:0:0:0: [sda] Add. Sense: Unrecovered read error - auto reallocate failed
[12345.678] end_request: I/O error, dev sda, sector 123456

An organization requires a disaster recovery site that can be operational within 24 hours after a disaster declaration, with critical data replicated on a regular basis, but not necessarily real-time. Which type of site should they implement?

A company performs a full backup on Sunday and incremental backups Monday through Saturday. A server fails on Thursday at 10:00 AM. Which sequence correctly restores the data?

A financial services firm requires a disaster recovery site that provides immediate failover with zero data loss. Which type of site should they implement?

An organization stores backup tapes at an offsite facility. The tapes contain sensitive customer data. A security audit revealed that tapes were stolen from the facility. Which combination of measures would have MOST effectively prevented unauthorized data access?

Refer to the exhibit. A backup job to a network share failed. The administrator reviews the backup log. What is the most likely cause of the failure?

Exhibit

Backup started at 02:00:00
Connecting to backup repository \backupserver\data...
Error: Access is denied.
Backup failed.

Refer to the exhibit. A Linux server's local firewall is configured as shown. The administrator is unable to perform backups to a network-attached storage (NAS) device using TCP port 10000. Which firewall rule is causing the issue?

Network Topology
0 0 DROP all* * 0.0.0.0/012 720 ACCEPT tcp# iptables -L -n -v

A database server hosts a critical application that requires a recovery point objective (RPO) of 4 hours. The company wants to minimize the impact on production performance during backups. Which backup strategy should be implemented?

A small business has a limited budget and can tolerate up to 72 hours of downtime in the event of a disaster. Which type of disaster recovery site would be most cost-effective?

After an unexpected power outage, a server fails to boot and displays an error indicating a degraded RAID array. The server has a RAID 5 configuration with four disks. One disk has failed, but the hot spare did not automatically rebuild. The administrator needs to restore data availability as quickly as possible. Which action should the technician take FIRST?

A system administrator needs to configure secure remote access to servers in the data center. The current setup uses password-based SSH, but the security policy mandates multifactor authentication and prevention of brute-force attacks. Which solution best meets these requirements?

A company performs annual disaster recovery tests. The last test revealed that the recovery time objective (RTO) was not met because the backup tapes were corrupted. The backup administrator proposes changes to the backup verification process. Which practice is MOST effective to ensure recoverability?

During a security incident, a server is suspected to be compromised by malware. The incident response team needs to preserve evidence and minimize impact. Which TWO actions should be taken FIRST? (Select TWO.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused security-disaster-recovery sessions

Start a security-disaster-recovery only practice session

Every question in these sessions is drawn from the security-disaster-recovery domain — nothing else.

Related practice questions

Related SK0-005 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SK0-005 exam test about security-disaster-recovery?
security-disaster-recovery questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just security-disaster-recovery questions in a focused session?
Yes — the session launcher on this page draws every question from the security-disaster-recovery domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SK0-005 topics?
Use the topic links above to move to related areas, or go back to the SK0-005 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SK0-005 exam covers. They are not copied from any real exam or dump site.